SCS-C02 Data Protection Practice Question
A company wants to protect data in transit between an on-premises data center and Amazon S3. Which AWS service should be used to establish a dedicated, encrypted connection?
⚠ Common exam trap
SCS-C02 often tests the misconception that Direct Connect is encrypted by default — candidates must remember that encryption requires an explicit IPsec VPN or MACsec layer on top of the dedicated connection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Direct Connect with an IPsec VPN
AWS Direct Connect alone provides a dedicated private network path but does not encrypt traffic in transit. To achieve both a dedicated connection and encryption, you must pair Direct Connect with an IPsec VPN running over the dedicated link. This combination gives the private, consistent bandwidth of Direct Connect plus the encryption guarantees of IPsec, satisfying the requirement for encrypted data in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Direct Connect without VPN
Why it's wrong here
AWS Direct Connect without VPN creates a private, dedicated physical link from your on-premises network to AWS, but it does not configure any encryption of the traffic flowing across that link. The link is isolated from the public internet, yet the data payloads remain in plaintext, so any compromise of the physical path or the intermediate infrastructure could expose sensitive information. Therefore, while it meets the 'dedicated' criterion, it fails to protect data in transit when encryption is a requirement.
- ✗
AWS Transit Gateway
Why it's wrong here
AWS Transit Gateway is not a connection at all; it is a network transit hub that routes traffic between VPCs, VPNs, and Direct Connect attachments. It enables you to manage many connections centrally but it does not itself provide the physical or encrypted path between an on-premises environment and AWS. Without an underlying transport like Direct Connect or an AWS Site-to-Site VPN, Transit Gateway has no means to carry or protect the data in transit.
- ✓
AWS Direct Connect with an IPsec VPN
Why this is correct
AWS Direct Connect with an IPsec VPN layers an encrypted VPN tunnel over a dedicated, private Direct Connect connection, giving you both isolation from the public internet and traffic confidentiality. The IPsec protocol authenticates and encrypts the packets, ensuring that data is protected in transit while still benefiting from the predictable latency and throughput of the physical link. This is the recommended pattern when you need both dedicated bandwidth and encryption.
- ✗
AWS Site-to-Site VPN over the internet
Why it's wrong here
AWS Site-to-Site VPN over the internet leverages an IPsec tunnel to encrypt traffic, but it uses the public internet as the underlying transport. Because the tunnel traverses the internet, it is subject to unpredictable latency, packet loss, and possible congestion, and it does not provide a private, dedicated path between your on-premises network and AWS. While it fulfills the encryption requirement, it fails the 'dedicated' requirement, making it unsuitable for the stated need.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.